On 2026-09-21 11:02, Patrick Proniewski via Postfix-users wrote:
In a not too distant future I might have to bring back at home my email self-hosted stack (Postfix, Dovecot, Webmail, all signing and filtering…). It currently sits in a datacenter with a good reputation IP address.
[snip]
I think signing (DKIM, ARC) at home, then forwarding to a postfix instance on the VPS for public delivery, is not best practice.
There's debate about this. I'm on the side of signing on the originating server. Plus signing on the MX VPS means storing your signing key on someone else's computer.
I’m running FreeBSD. I’ve created a Jail with Wireguard client, a VPN tunnel between the Jail and the Wireguard server on the VPS, but I could not find a way to use that setup properly.
FWIW, I do this with the TLS secure channel capabilities of Postfix combined with certificate-based authentication, and separate inbound and outbound transports.
_______________________________________________ Postfix-users mailing list -- [email protected] To unsubscribe send an email to [email protected]
